From 253e3e7f2e965d98f06caa9e3c88f64863463149 Mon Sep 17 00:00:00 2001 From: Patrick Dawkins Date: Fri, 25 Sep 2026 15:57:45 +0100 Subject: [PATCH 1/2] fix(macos): build x86_64 with the standalone spc binary setup-php no longer supports Intel macOS runners, since Homebrew dropped them: the macOS x86_64 job hung for ~27 minutes in "Setup PHP" and then failed with "Could not setup PHP 8.4", so no release was created. Download the standalone spc binary of the pinned static-php-cli release instead of cloning it, which needs no PHP or Composer on the runner. See: https://github.com/shivammathur/setup-php/issues/1112 Co-Authored-By: Claude Opus 5.5 --- .github/workflows/build-php.yml | 24 ++++++++++-------------- 1 file changed, 10 insertions(+), 14 deletions(-) diff --git a/.github/workflows/build-php.yml b/.github/workflows/build-php.yml index d86a30e..288b1a6 100644 --- a/.github/workflows/build-php.yml +++ b/.github/workflows/build-php.yml @@ -166,26 +166,22 @@ jobs: retention-days: 1 # macOS x86_64 (Intel) build + # Uses the standalone spc binary, as setup-php no longer supports Intel macOS + # runners (Homebrew dropped them). + # See: https://github.com/shivammathur/setup-php/issues/1112 build-macos-amd64: name: macOS x86_64 needs: resolve-version runs-on: macos-15-intel steps: - - name: Clone static-php-cli - run: | - git clone --depth 1 --branch ${{ env.SPC_VERSION }} https://github.com/crazywhalecc/static-php-cli.git spc - - - name: Setup PHP - uses: shivammathur/setup-php@v2 - with: - php-version: '8.4' - tools: composer - extensions: curl, openssl, mbstring - - - name: Install dependencies + - name: Download static-php-cli run: | - cd spc - composer install --no-dev --classmap-authoritative + mkdir spc + curl -fsSL "https://github.com/crazywhalecc/static-php-cli/releases/download/${{ env.SPC_VERSION }}/spc-macos-x86_64.tar.gz" \ + | tar -xz -C spc + mkdir spc/bin + mv spc/spc spc/bin/spc + spc/bin/spc --version - name: Setup build environment run: | From a67f1057dffdd7d5df8978c896481380071157f7 Mon Sep 17 00:00:00 2001 From: Patrick Dawkins Date: Fri, 25 Sep 2026 16:21:11 +0100 Subject: [PATCH 2/2] fix(macos): verify the spc download before extracting it Address review feedback: - Check the tarball against a pinned SHA-256, since a release asset can be replaced after upload and the binary builds the published PHP. The hash matches the digest GitHub recorded for the 2.8.5 asset. - Download to a file instead of piping curl into tar, so a failed download fails the step at curl rather than later at a missing file. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/build-php.yml | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/.github/workflows/build-php.yml b/.github/workflows/build-php.yml index 288b1a6..8ed2e38 100644 --- a/.github/workflows/build-php.yml +++ b/.github/workflows/build-php.yml @@ -26,6 +26,8 @@ on: env: SPC_VERSION: '2.8.5' + # SHA-256 of spc-macos-x86_64.tar.gz in the SPC_VERSION release. + SPC_MACOS_X86_64_SHA256: 'e8b798048f62ca4960764196543b60ae703f7174aa418824cf542aeec1d2cd6a' GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} jobs: @@ -176,11 +178,10 @@ jobs: steps: - name: Download static-php-cli run: | - mkdir spc - curl -fsSL "https://github.com/crazywhalecc/static-php-cli/releases/download/${{ env.SPC_VERSION }}/spc-macos-x86_64.tar.gz" \ - | tar -xz -C spc - mkdir spc/bin - mv spc/spc spc/bin/spc + curl -fsSL -o spc.tar.gz "https://github.com/crazywhalecc/static-php-cli/releases/download/${{ env.SPC_VERSION }}/spc-macos-x86_64.tar.gz" + echo "${{ env.SPC_MACOS_X86_64_SHA256 }} spc.tar.gz" | shasum -a 256 -c + mkdir -p spc/bin + tar -xzf spc.tar.gz -C spc/bin spc/bin/spc --version - name: Setup build environment